First published: Thu Jan 23 2020(Updated: )
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6843 is medium with a score of 4.8.
CVE-2020-6843 allows for cross-site scripting (XSS) attacks in Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007.
Yes, CVE-2020-6843 has been fixed in version 11.0 Build 11010 of Zoho ManageEngine ServiceDesk Plus.
The CWE ID for CVE-2020-6843 is CWE-79.
You can find more information about CVE-2020-6843 on the following websites: [http://packetstormsecurity.com/files/156050/ZOHO-ManageEngine-ServiceDeskPlus-11.0-Build-11007-Cross-Site-Scripting.html](http://packetstormsecurity.com/files/156050/ZOHO-ManageEngine-ServiceDeskPlus-11.0-Build-11007-Cross-Site-Scripting.html), [http://seclists.org/fulldisclosure/2020/Jan/32](http://seclists.org/fulldisclosure/2020/Jan/32), [https://sec-consult.com/en/vulnerability-lab/advisories/index.html](https://sec-consult.com/en/vulnerability-lab/advisories/index.html).